CVE-2024-11614

EUVD-2024-34403
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Debian logo
Debian Releases
Debian Product
Codename
dpdk
bookworm
22.11.9-1~deb12u1
fixed
bookworm (security)
22.11.7-1~deb12u1
fixed
bullseye
20.11.10-1~deb11u1
not-affected
bullseye (security)
20.11.6-1~deb11u1
fixed
forky
25.11-2
fixed
sid
25.11-2
fixed
trixie
24.11.3-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dpdk
bionic
not-affected
focal
not-affected
jammy
Fixed 21.11.6-0ubuntu0.22.04.2
released
noble
Fixed 23.11-1ubuntu0.1
released
oracular
Fixed 23.11.2-0ubuntu1.1
released
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dpdk
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise sap 15 SP7
24.11.1-150700.1.17
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.17
fixed
dpdk-devel
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise sap 15 SP7
24.11.1-150700.1.17
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.17
fixed
dpdk-thunderx
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise sap 15 SP7
24.11.1-150700.1.15
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.15
fixed
dpdk-thunderx-devel
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise sap 15 SP7
24.11.1-150700.1.15
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.15
fixed
dpdk-tools
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise sap 15 SP7
24.11.1-150700.1.17
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.17
fixed
libdpdk-23
suse enterprise sap 15 SP6
22.11.1-150600.3.9.1
fixed
suse enterprise server 15 SP6
22.11.1-150600.3.9.1
fixed
libdpdk-25
suse enterprise sap 15 SP7
24.11.1-150700.1.17
fixed
suse enterprise server 15 SP7
24.11.1-150700.1.17
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
dpdk
RHEL 8
0:23.11-2.el8_10
fixed
RHEL 8.6 AUS
0:21.11-3.el8_6
fixed
RHEL 8.6 E4S
0:21.11-3.el8_6
fixed
RHEL 8.6 TUS
0:21.11-3.el8_6
fixed
RHEL 8.8 AUS
0:21.11-4.el8_8
fixed
RHEL 8.8 E4S
0:21.11-4.el8_8
fixed
RHEL 8.8 EUS
0:21.11-4.el8_8
fixed
RHEL 8.8 TUS
0:21.11-4.el8_8
fixed
RHEL 9
2:23.11-2.el9_5
fixed
dpdk-devel
RHEL 8
0:23.11-2.el8_10
fixed
RHEL 8.6 AUS
0:21.11-3.el8_6
fixed
RHEL 8.6 E4S
0:21.11-3.el8_6
fixed
RHEL 8.6 TUS
0:21.11-3.el8_6
fixed
RHEL 8.8 AUS
0:21.11-4.el8_8
fixed
RHEL 8.8 E4S
0:21.11-4.el8_8
fixed
RHEL 8.8 EUS
0:21.11-4.el8_8
fixed
RHEL 8.8 TUS
0:21.11-4.el8_8
fixed
RHEL 9
2:23.11-2.el9_5
fixed
dpdk-doc
RHEL 8
0:23.11-2.el8_10
fixed
RHEL 8.6 AUS
0:21.11-3.el8_6
fixed
RHEL 8.6 E4S
0:21.11-3.el8_6
fixed
RHEL 8.6 TUS
0:21.11-3.el8_6
fixed
RHEL 8.8 AUS
0:21.11-4.el8_8
fixed
RHEL 8.8 E4S
0:21.11-4.el8_8
fixed
RHEL 8.8 EUS
0:21.11-4.el8_8
fixed
RHEL 8.8 TUS
0:21.11-4.el8_8
fixed
RHEL 9
2:23.11-2.el9_5
fixed
dpdk-tools
RHEL 8
0:23.11-2.el8_10
fixed
RHEL 8.6 AUS
0:21.11-3.el8_6
fixed
RHEL 8.6 E4S
0:21.11-3.el8_6
fixed
RHEL 8.6 TUS
0:21.11-3.el8_6
fixed
RHEL 8.8 AUS
0:21.11-4.el8_8
fixed
RHEL 8.8 E4S
0:21.11-4.el8_8
fixed
RHEL 8.8 EUS
0:21.11-4.el8_8
fixed
RHEL 8.8 TUS
0:21.11-4.el8_8
fixed
RHEL 9
2:23.11-2.el9_5
fixed